That's the ideal state, isn't it? A due diligence that’s based on how you’re actually planning to use the vendor and the risks associated with it. Not this risk management theatre that TPRM is.
Does this now allow us to assign enterprise risks without giving broader permissions? My CFO doesn't need admin access, but does need to own our financial risks